Test & Evaluation¶
This section outlines the components that have been identified for the Test & Evaluation dimension as well as the levels within the components. These components and levels form the basis for assessing how threat informed an organization’s T&E program is.
Type of Testing¶
What type of security tests are conducted to evaluate defensive measures?
Reactive, compliance-focused, e.g. security control assessment
Reactive, IOC-focused, e.g. vulnerability assessment
Proactive, threat-focused, e.g. adversary emulation
Proactive, threat-focused, collaborative, e.g. Purple Team
Frequency of Testing¶
How frequently are security tests conducted?
Annual or Ad hoc
Semi-Annual
Monthly
Continuous
Test Planning¶
Are tests coordinated and prioritized on the most relevant threat behaviors?
No formal planning or ad hoc planning
Deliberately planned and scoped, informed by threats
Collaboratively planned with defenders, focused on known gaps and validating coverage
Collaboratively planned with defenders, linked to organizational metrics or KPIs
Test Execution¶
Does testing cover adversary TTPs in addition to traditional IOCs?
Not threat-focused, e.g. scanners
IOC-focused, e.g. commodity tooling
TTP-focused, single procedures of techniques
TTP-focused, multiple procedures of techniques, custom tooling
Test Results¶
How effectively do test results cause improvements in defensive measures?
Results generated
Actions taken with internal team, e.g. playbooks updated
Results formally tracked; findings drive detection improvements and architectural changes
Results formally tracked; findings drive organizational programs, hiring, training, and other significant investments